Apache Log4j Vulnerabilities with PME
Issue
Are there any Apache Log4j vulnerabilities in relation to Power Monitoring Expert Software?
Resolution
Apache Log4j is an open-source 3rd-party Java component that is widely used to add event/error logging to existing software platforms. It suffered a series of critical vulnerabilities known as Log4Shell in versions 2.0 - 2.14.1. The most severe flaws allow attackers to execute remote code on targeted servers.
Apache Log4j issues do not affect Power Monitoring Expert Software; the vulnerability applies to certain versions of Windows software such as SQL Server.
The base install of SQL Server 2019 uses Apache Log4j version 1.2.17. Although this older version of Log4j does not have the same security issues as versions 2.x, a lot of scanners recommend to remove older versions as good practice.
Organizations should immediately upgrade to Log4j 2.17.1 or higher to fully patch these vulnerabilities. However Windows created a Cumulative Update (16) for SQL Server 2019 that removes the flagged files: (Microsoft is currently up to CU 32 for SQL 2019).
https://learn.microsoft.com/en-us/troubleshoot/sql/releases/sqlserver-2019/cumulativeupdate16
Bug reference - 14669019
Description - Removes log4j2 used by SQL Server 2019 Integration Services (SSIS) to avoid any potential security issues
Fix area - Integration Services
Component Platform - DTS
Reference discussion: https://learn.microsoft.com/en-us/answers/questions/707615/updating-apache-log4j-on-sql-2019-installations
Here is a link to all the Cumulative Updates for SQL 2019 - https://learn.microsoft.com/en-us/troubleshoot/sql/releases/sqlserver-2019/build-versions